Executive brief
MindsDB is an open-source AI/ML platform that allows users to upload and extract archive files (tarballs). The application downloads remote tarballs and extracts them without validating file paths, allowing an attacker to craft a malicious tarball that writes files outside the intended directory. An attacker could overwrite critical system files, potentially compromising server integrity and availability.
Technical details
The vulnerability is a path traversal flaw (CWE-22, also known as TarSlip) in MindsDB's file extraction functionality in file.py. The application uses tarfile.extractall() to extract remotely retrieved tarballs without sanitizing or validating member file paths. An attacker can craft a tarball containing entries with path traversal sequences (e.g., "../../../../etc/passwd") or absolute paths that cause files to be written outside the intended extraction directory. The attack requires network access to the MindsDB API's PUT endpoint and the ability to serve a malicious tarball remotely. No authentication bypass is needed if the endpoint is publicly accessible. The fix was released in version 23.2.1.0.
Affected products
- MindsDB MindsDB before 23.2.1.0
Timeline
- 2023-03-30: disclosed
- 2023: patched: Fixed in version 23.2.1.0